Community discussions

MikroTik App
 
Eduardo
newbie
Topic Author
Posts: 45
Joined: Thu Aug 18, 2016 12:20 pm

Firewall for site-to-site VPN

Mon Aug 22, 2016 2:07 pm

When setting up a site-to-site VPN (via IPSec), it is apparently not necessary to open the firewall?
How can this be explained? :-)

Thanks...
 
pe1chl
Forum Guru
Forum Guru
Posts: 10513
Joined: Mon Jun 08, 2015 12:09 pm

Re: Firewall for site-to-site VPN

Mon Aug 22, 2016 2:56 pm

Do you do direct IPsec tunnel? It behaves a bit funny, due to the way it integrates with the network. This is quite usual in IPsec implementations.
When you don't want that, use a tunnel interface (IP Tunnel, GRE Tunnel) with IPsec protection configured.
Then you can have the usual firewall rules on the tunnel interface.
(it is possible with direct IPsec tunnel as well, but rather complicated)

Who is online

Users browsing this forum: CzechDaniel and 22 guests